SV-220344r960882_rule
V-220344
SRG-APP-000090-DB-000065
ML09-00-000600
CAT II
10
Configure the DBMS's settings to allow designated personnel to select which auditable events are audited.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Roles assigned to the Users. For designated personnel, assign the admin role and change user roles as necessary.
4. Inspect the Roles assigned to the Users. For non-designated personnel, remove the admin role and change user roles as necessary.
Check MarkLogic settings and documentation to determine whether designated personnel are able to select which auditable events are being audited.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Roles assigned to the Users. If a User who is designated personnel does not have the admin role, this is a finding.
4. Inspect the Roles assigned to the Users. If a User who is not designated personnel has the admin role, this is a finding.
V-220344
False
ML09-00-000600
Check MarkLogic settings and documentation to determine whether designated personnel are able to select which auditable events are being audited.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Roles assigned to the Users. If a User who is designated personnel does not have the admin role, this is a finding.
4. Inspect the Roles assigned to the Users. If a User who is not designated personnel has the admin role, this is a finding.
M
4064